opacus
Train PyTorch models with Differential Privacy
Decision gist · record as of 2026-08-14
Yes, if you need to train PyTorch models with formal differential privacy guarantees. The library is actively maintained, has low installation friction, carries a permissive license, and integrates cleanly into existing PyTorch workflows. Install if privacy-preserving training is a requirement; skip if you have no privacy constraints.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires torch and numpy.
- Model architecture must be compatible with DP-SGD (some layer types may need validation via Opacus's module validator).
- Low friction installation with a pure Python wheel.
License · maintenance · safety
Apache-2.0 (permissive) — Released under Apache-2.0 (permissive), allowing commercial and private use with minimal restrictions. You may use, modify, and distribute the code freely provided you include the license notice.
last release 2026-05-05 (101 days) · last repo commit 2026-07-13 · 1,949 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 170,543 downloads/mo, #10,391 on PyPI
Alternatives
Verify before relying
pip install opacus
from opacus import PrivacyEngine
import torch
model = Net()
optimizer = torch.optim.SGD(model.parameters(), lr=0.05)
data_loader = torch.utils.data.DataLoader(dataset, batch_size=1024)
privacy_engine = PrivacyEngine()
model, optimizer, data_loader = privacy_engine.make_private(
module=model,
optimizer=optimizer,
data_loader=data_loader,
noise_multiplier=1.1,
max_grad_norm=1.0,
)- Performance overhead compared to standard PyTorch training under typical workloads
- Compatibility with specific PyTorch versions beyond the stated Python 3.7.5+ requirement
- Memory savings quantified for the Ghost Clipping feature mentioned in recent updates
What it is and what it does
Opacus is a PyTorch library that adds differential privacy to model training through DP-SGD (Differentially Private Stochastic Gradient Descent). It wraps your existing model, optimizer, and data loader with privacy-aware counterparts via a PrivacyEngine, allowing you to train with formal privacy guarantees while monitoring privacy budget expenditure in real time.
The library targets both ML practitioners seeking an accessible introduction to privacy-preserving training and differential privacy researchers needing flexibility for experimentation. It depends on numpy, torch, scipy, and opt-einsum, and recent updates have introduced Fast Gradient Clipping and Ghost Clipping to reduce memory overhead during training.
Use it for
- Train models on sensitive data (medical records, financial data) with formal privacy guarantees for regulatory compliance
- Federated learning scenarios where model updates must not leak information about individual training samples
- Research into differential privacy algorithms and DP-SGD variants with minimal boilerplate
- Building text classifiers on BERT with privacy (as shown in updated tutorials with LoRA/peft integration)
- Image classification tasks where privacy budget must be tracked and controlled throughout training
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need to train PyTorch models with formal differential privacy guarantees.
The library is actively maintained, has low installation friction, carries a permissive license, and integrates cleanly into existing PyTorch workflows. Install if privacy-preserving training is a requirement; skip if you have no privacy constraints.
Install
opacus on PyPI
Before you install
Low friction installation with a pure Python wheel. Active maintenance with recent updates (2024-12-18 and 2024-08-20) including Fast Gradient Clipping and Ghost Clipping features. Repository shows 1949 stars and active development.
Requires torch and numpy. Model architecture must be compatible with DP-SGD (some layer types may need validation via Opacus's module validator).
License in practice
Released under Apache-2.0 (permissive), allowing commercial and private use with minimal restrictions. You may use, modify, and distribute the code freely provided you include the license notice.
Quickstart
pip install opacus
from opacus import PrivacyEngine
import torch
model = Net()
optimizer = torch.optim.SGD(model.parameters(), lr=0.05)
data_loader = torch.utils.data.DataLoader(dataset, batch_size=1024)
privacy_engine = PrivacyEngine()
model, optimizer, data_loader = privacy_engine.make_private(
module=model,
optimizer=optimizer,
data_loader=data_loader,
noise_multiplier=1.1,
max_grad_norm=1.0,
)
Verify before relying
- Performance overhead compared to standard PyTorch training under typical workloads
- Compatibility with specific PyTorch versions beyond the stated Python 3.7.5+ requirement
- Memory savings quantified for the Ghost Clipping feature mentioned in recent updates
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.7.5 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 4 packagesnumpytorchscipyopt-einsum |
| Maintenance | Actively maintained 101 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 170,543 / month, #10,391 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaIntended Audience :: DevelopersIntended Audience :: EducationIntended Audience :: Science/ResearchLicense :: OSI Approved :: Apache Software LicenseProgramming Language :: Python :: 3 :: OnlyTopic :: Scientific/Engineering |
Evidence: opacus-1.6.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “differential privacy pytorch”
- opacusOpacus enables training PyTorch models with differential privacy…
- torchsdeSolves stochastic differential equations (SDEs) with GPU support and…
- torchcdeProvides differentiable GPU-capable solvers for controlled…
Give your agent the search over MCP, or paste the wish link into any chat.
More Scientific/Engineering packages
NumPy provides an N-dimensional array object and a comprehensive suite of mathematical, linear algebra, Fourier transform, and random number functions for scientific computing in Python.
pandas provides fast, flexible data structures (Series and DataFrame) for loading, cleaning, transforming, and analyzing labeled or relational data in Python.
scipy provides numerical algorithms for mathematics, science, and engineering—including optimization, integration, linear algebra, Fourier transforms, signal and image processing, and ODE solvers—built on numpy arrays.
scikit-learn provides a comprehensive Python library for supervised and unsupervised machine learning, including classification, regression, clustering, dimensionality reduction, and model evaluation tools built on NumPy and SciPy.
Install it if you need to train, evaluate, or deploy supervised or unsupervised learning models.
dill extends Python's pickle module to serialize and deserialize a much wider range of Python objects, including functions, lambdas, classes, and interpreter sessions, to byte streams for storage or network transmission.
Multiprocess is an enhanced fork of Python's standard multiprocessing library that uses dill for better serialization, allowing you to spawn processes with a threading-like API and share complex objects between them.
Install it if you use multiprocessing and encounter pickle serialization limits with lambdas or complex objects.
See also torchsde · pytorch-ranger · torch · zuko · accelerate · adam-atan2-pytorch · k-diffusion · pytorch-forecasting · flashoptim · pytorch_optimizer